The following Fedora 24 Security updates need testing: Age URL 24 https://bodhi.fedoraproject.org/updates/FEDORA-2016-95edf19d8a squid-3.5.19-2.fc24 19 https://bodhi.fedoraproject.org/updates/FEDORA-2016-dfa325d31b community-mysql-5.7.12-1.fc24 10 https://bodhi.fedoraproject.org/updates/FEDORA-2016-50b0066b7f ntp-4.2.6p5-41.fc24 4 https://bodhi.fedoraproject.org/updates/FEDORA-2016-e0f3fcd7df kernel-4.5.7-300.fc24 1 https://bodhi.fedoraproject.org/updates/FEDORA-2016-44821f9576 mxml-2.9-1.fc24 1 https://bodhi.fedoraproject.org/updates/FEDORA-2016-a771d67ba0 nfdump-1.6.15-1.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d5917e939e python-2.7.11-5.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-22eab18150 python3-3.5.1-8.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-cf396bc041 xen-4.6.1-12.fc24 The following Fedora 24 Critical Path updates have yet to be approved: Age URL 12 https://bodhi.fedoraproject.org/updates/FEDORA-2016-3d4c0d27b6 clementine-1.3.1-2.fc24 sqlite-3.12.2-1.fc24 10 https://bodhi.fedoraproject.org/updates/FEDORA-2016-41bde7479f lorax-24.19-1.fc24 9 https://bodhi.fedoraproject.org/updates/FEDORA-2016-3a7f36c0c1 vim-7.4.1868-1.fc24 4 https://bodhi.fedoraproject.org/updates/FEDORA-2016-e0f3fcd7df kernel-4.5.7-300.fc24 4 https://bodhi.fedoraproject.org/updates/FEDORA-2016-52fd6003b8 librsvg2-2.40.16-1.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-a8ecdc2c01 anaconda-24.13.7-1.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-743d2f9c4c mutter-3.20.2-2.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d5917e939e python-2.7.11-5.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-ab6fa06b1c thunderbird-45.1.1-2.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-3bbae10376 perl-5.22.2-360.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-4c80727621 util-linux-2.28-3.fc24 0 https://bodhi.fedoraproject.org/updates/FEDORA-2016-5437995928 lvm2-2.02.150-2.fc24 The following builds have been pushed to Fedora 24 updates-testing 389-ds-base-1.3.5.5-1.fc24 anaconda-24.13.7-1.fc24 azureus-5.7.2.0-1.fc24 cdbs-0.4.139-1.fc24 clamav-0.99.2-1.fc24 diffoscope-54-1.fc24 elog-3.1.1-5.fc24 erlang-18.3.3-2.fc24 gssproxy-0.5.1-1.fc24 guayadeque-0.4.1-0.9.beta1gitf6b11ba.fc24 hadoop-2.4.1-17.fc24 jsoncpp-1.7.2-2.fc24 libguestfs-1.33.36-1.fc24 man-pages-4.06-2.fc24 man-pages-de-1.12-3.fc24 man-pages-es-1.55-26.fc24 man-pages-ja-20151215-4.fc24 man-pages-ko-20050219-30.fc24 man-pages-pl-0.6-5.fc24 man-pages-ru-3.81-4.20151031.fc24 mutter-3.20.2-2.fc24 nc6-1.0-24.fc24 nodejs-rhea-0.1.6-1.fc24 pbuilder-0.225-1.fc24 psi4-1.0-0.1.rc.15fc63cgit.fc24 python-regex-2016.06.05-1.fc24 python3-3.5.1-8.fc24 qupzilla-2.0.1-1.fc24 qutebrowser-0.7.0-1.fc24 rekall-2.4.6-32.fc24 sip-4.18-2.fc24 xen-4.6.1-12.fc24 Details about builds: ================================================================================ 389-ds-base-1.3.5.5-1.fc24 (FEDORA-2016-5c965fe227) 389 Directory Server (base) -------------------------------------------------------------------------------- Update Information: Release 1.3.5.5-1 -------------------------------------------------------------------------------- ================================================================================ anaconda-24.13.7-1.fc24 (FEDORA-2016-a8ecdc2c01) Graphical system installer -------------------------------------------------------------------------------- Update Information: - Revert "Check for mounted partitions as part of sanity_check" -------------------------------------------------------------------------------- References: [ 1 ] Bug #1344863 - AttributeError: 'Iso9660FS' object has no attribute 'partitions' https://bugzilla.redhat.com/show_bug.cgi?id=1344863 -------------------------------------------------------------------------------- ================================================================================ azureus-5.7.2.0-1.fc24 (FEDORA-2016-7ddcbc0d1e) A BitTorrent Client -------------------------------------------------------------------------------- Update Information: Upgrade to 5.7.2.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1336076 - azureus-5720 is available https://bugzilla.redhat.com/show_bug.cgi?id=1336076 -------------------------------------------------------------------------------- ================================================================================ cdbs-0.4.139-1.fc24 (FEDORA-2016-d49007635d) Common build system for Debian packages -------------------------------------------------------------------------------- Update Information: Update to version 0.4.139, see http://metadata.ftp- master.debian.org/changelogs//main/c/cdbs/cdbs_0.4.139_changelog for details. -------------------------------------------------------------------------------- ================================================================================ clamav-0.99.2-1.fc24 (FEDORA-2016-54667db84b) End-user tools for the Clam Antivirus scanner -------------------------------------------------------------------------------- Update Information: Update to 0.99.2, see http://blog.clamav.net/2016/05/clamav-0992-has-been- released.html - Drop cliopts patch fixed upstream, use upstream's "-- foreground" option name - Fix main.cvd (fedora #1325482, epel #1325717) - Own bytecode.cld (#1176252) and mirrors.dat, ship bytecode.cvd - Update daily.cvd - Fixup Requires(pre) usage (#1319151) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1333949 - clamav-0.99.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1333949 [ 2 ] Bug #1325482 - The main.cvd database in clamav-data-0.99.1-1 is corrupt https://bugzilla.redhat.com/show_bug.cgi?id=1325482 -------------------------------------------------------------------------------- ================================================================================ diffoscope-54-1.fc24 (FEDORA-2016-ea5eaf6121) In-depth comparison of files, archives, and directories -------------------------------------------------------------------------------- Update Information: Update to latest version. -------------------------------------------------------------------------------- ================================================================================ elog-3.1.1-5.fc24 (FEDORA-2016-323afbeadb) Logbook system to manage notes through a Web interface -------------------------------------------------------------------------------- Update Information: Logbook system to manage notes through a web interface -------------------------------------------------------------------------------- References: [ 1 ] Bug #1302504 - Review Request: elog - Logbook system to manage notes through a Web interface https://bugzilla.redhat.com/show_bug.cgi?id=1302504 -------------------------------------------------------------------------------- ================================================================================ erlang-18.3.3-2.fc24 (FEDORA-2016-9ded469f1b) General-purpose programming language and runtime environment -------------------------------------------------------------------------------- Update Information: * Fix regression with GCC 6.x.y -------------------------------------------------------------------------------- References: [ 1 ] Bug #1316206 - erl_interface: regression in erl_decode for LLONG_MIN longlong value https://bugzilla.redhat.com/show_bug.cgi?id=1316206 -------------------------------------------------------------------------------- ================================================================================ gssproxy-0.5.1-1.fc24 (FEDORA-2016-fb765637bd) GSSAPI Proxy -------------------------------------------------------------------------------- Update Information: Upstream bugfix release. Known to resolve issues with autofs. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1345871 - Cannot mount NFSv4 export with krb5 auth exported from Fedora 24 server https://bugzilla.redhat.com/show_bug.cgi?id=1345871 -------------------------------------------------------------------------------- ================================================================================ guayadeque-0.4.1-0.9.beta1gitf6b11ba.fc24 (FEDORA-2016-a8feeda699) Music player -------------------------------------------------------------------------------- Update Information: - Dropped Provides: bundled(wxcurl) = wxcurl_version wxcurl was replaced by libcurl library directly - Update to 0.4.1-0.9.beta1gitf6b11ba -------------------------------------------------------------------------------- ================================================================================ hadoop-2.4.1-17.fc24 (FEDORA-2016-9f87727448) A software platform for processing vast amounts of data -------------------------------------------------------------------------------- Update Information: Fix broken deps in F24 stable repo -------------------------------------------------------------------------------- References: [ 1 ] Bug #1346006 - hadoop retirement breaks deps in F24 base repo https://bugzilla.redhat.com/show_bug.cgi?id=1346006 -------------------------------------------------------------------------------- ================================================================================ jsoncpp-1.7.2-2.fc24 (FEDORA-2016-2eb79bedb8) JSON library implemented in C++ -------------------------------------------------------------------------------- Update Information: Fix include dir path (#1336082) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1336082 - bad path, jsoncpp.pc include dir https://bugzilla.redhat.com/show_bug.cgi?id=1336082 -------------------------------------------------------------------------------- ================================================================================ libguestfs-1.33.36-1.fc24 (FEDORA-2016-e5edf9156e) Access and modify virtual machine disk images -------------------------------------------------------------------------------- Update Information: New upstream version 1.33.36. -------------------------------------------------------------------------------- ================================================================================ man-pages-4.06-2.fc24 (FEDORA-2016-1b4243e1a8) Linux kernel and C library user-space interface documentation -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-de-1.12-3.fc24 (FEDORA-2016-1b4243e1a8) German man pages from the Linux Documentation Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-es-1.55-26.fc24 (FEDORA-2016-1b4243e1a8) Spanish man pages from the Linux Documentation Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-ja-20151215-4.fc24 (FEDORA-2016-1b4243e1a8) Japanese man (manual) pages from the Japanese Manual Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-ko-20050219-30.fc24 (FEDORA-2016-1b4243e1a8) Korean(Hangul) Man(manual) Pages from the Korean Manpage Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-pl-0.6-5.fc24 (FEDORA-2016-1b4243e1a8) Polish man pages from the Linux Documentation Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ man-pages-ru-3.81-4.20151031.fc24 (FEDORA-2016-1b4243e1a8) Russian man pages from the Linux Documentation Project -------------------------------------------------------------------------------- Update Information: Remove non-free man pages. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1334279 - man-pages included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334279 [ 2 ] Bug #1334281 - man-page-de included non-free docs. https://bugzilla.redhat.com/show_bug.cgi?id=1334281 [ 3 ] Bug #1334282 - man-pages-es included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334282 [ 4 ] Bug #1334290 - man-pages-ko included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334290 [ 5 ] Bug #1334288 - man-pages-ja included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334288 [ 6 ] Bug #1334291 - man-pages-pl included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334291 [ 7 ] Bug #1334292 - man-pages-ru included non-free docs https://bugzilla.redhat.com/show_bug.cgi?id=1334292 -------------------------------------------------------------------------------- ================================================================================ mutter-3.20.2-2.fc24 (FEDORA-2016-743d2f9c4c) Window and compositing manager based on Clutter -------------------------------------------------------------------------------- Update Information: Fix for bug 1331382 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1331382 - Anaconda layout indicator does not switch the keyboard layout when clicked when running in Workstation live https://bugzilla.redhat.com/show_bug.cgi?id=1331382 -------------------------------------------------------------------------------- ================================================================================ nc6-1.0-24.fc24 (FEDORA-2016-9f87727448) Netcat with IPv6 Support -------------------------------------------------------------------------------- Update Information: Fix broken deps in F24 stable repo -------------------------------------------------------------------------------- References: [ 1 ] Bug #1346006 - hadoop retirement breaks deps in F24 base repo https://bugzilla.redhat.com/show_bug.cgi?id=1346006 -------------------------------------------------------------------------------- ================================================================================ nodejs-rhea-0.1.6-1.fc24 (FEDORA-2016-e931871103) A reactive messaging library based on the AMQP protocol -------------------------------------------------------------------------------- Update Information: Rebased to 0.1.6. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1343057 - nodejs-rhea-0.1.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1343057 [ 2 ] Bug #1341432 - nodejs-rhea-0.1.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1341432 -------------------------------------------------------------------------------- ================================================================================ pbuilder-0.225-1.fc24 (FEDORA-2016-a4f9deab4b) Personal package builder for Debian packages -------------------------------------------------------------------------------- Update Information: Update to version 0.225, see http://metadata.ftp- master.debian.org/changelogs//main/p/pbuilder/pbuilder_0.225_changelog for details. -------------------------------------------------------------------------------- ================================================================================ psi4-1.0-0.1.rc.15fc63cgit.fc24 (FEDORA-2016-a15d0cbac1) An ab initio quantum chemistry package -------------------------------------------------------------------------------- Update Information: Update to the first release candidate. This update fixes e.g. bugs with CI calculations. -------------------------------------------------------------------------------- ================================================================================ python-regex-2016.06.05-1.fc24 (FEDORA-2016-64c662cbeb) Alternative regular expression module, to replace re -------------------------------------------------------------------------------- Update Information: Update to the latest stable version. -------------------------------------------------------------------------------- ================================================================================ python3-3.5.1-8.fc24 (FEDORA-2016-22eab18150) Version 3 of the Python programming language aka Python 3000 -------------------------------------------------------------------------------- Update Information: Added patch for fixing possible integer overflow and heap corruption in zipimporter.get_data() -------------------------------------------------------------------------------- References: [ 1 ] Bug #1345859 - python3: python: Heap overflow in zipimporter module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1345859 -------------------------------------------------------------------------------- ================================================================================ qupzilla-2.0.1-1.fc24 (FEDORA-2016-4cae92a5dd) Modern web browser -------------------------------------------------------------------------------- Update Information: An update of QupZilla to version 2.0.1, the latest upstream bugfix release. Fixes: * don't force enabling HighDPI scaling by default * fix crash when unloading AutoScroll plugin * fix showing Inspect Element action when web inspector is disabled * fix showing context menu when page zoom is not 100% * fix destroying WebPage when opened as popup * fix setting default font families * fix saving last download path in download manager * fix using external download manager * fix canceling http and proxy authentication dialogs -------------------------------------------------------------------------------- ================================================================================ qutebrowser-0.7.0-1.fc24 (FEDORA-2016-3c02075805) A keyboard-driven, vim-like browser based on PyQt5 and QtWebKit -------------------------------------------------------------------------------- Update Information: Update to 0.7.0 -------------------------------------------------------------------------------- ================================================================================ rekall-2.4.6-32.fc24 (FEDORA-2016-a64ddd22c7) A KDE database front-end application -------------------------------------------------------------------------------- Update Information: Fix incorrect URL, fix building so that it works again. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1318479 - wrong URL https://bugzilla.redhat.com/show_bug.cgi?id=1318479 -------------------------------------------------------------------------------- ================================================================================ sip-4.18-2.fc24 (FEDORA-2016-0898eb66d2) SIP - Python/C++ Bindings Generator -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for: * proper out-of-src-tree builds * diamond inheritance patterns -------------------------------------------------------------------------------- References: [ 1 ] Bug #1345953 - Diamond inheritance issue https://bugzilla.redhat.com/show_bug.cgi?id=1345953 -------------------------------------------------------------------------------- ================================================================================ xen-4.6.1-12.fc24 (FEDORA-2016-cf396bc041) Xen is a virtual machine monitor -------------------------------------------------------------------------------- Update Information: fix systemd build issue on F25 Qemu: scsi: esp: OOB r/w access while processing ESP_FIFO [CVE-2016-5338] (#1343323) Qemu: scsi: megasas: information leakage in megasas_ctrl_get_info [CVE-2016-5337] (#1343909) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1343323 - CVE-2016-5338 Qemu: scsi: esp: OOB r/w access while processing ESP_FIFO https://bugzilla.redhat.com/show_bug.cgi?id=1343323 [ 2 ] Bug #1343909 - CVE-2016-5337 Qemu: scsi: megasas: information leakage in megasas_ctrl_get_info https://bugzilla.redhat.com/show_bug.cgi?id=1343909 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://lists.fedoraproject.org/admin/lists/test@xxxxxxxxxxxxxxxxxxxxxxx